ics-otregulatorNewsThe Broadside1 min read

CISA flags PAN-OS flaws in Siemens RUGGEDCOM APE1808

Firewall software vulnerabilities become industrial-appliance risk once they ride inside OT network gear.


TL;DR

CISA republished a Siemens ProductCERT advisory for all Siemens RUGGEDCOM APE1808 devices running Palo Alto Networks Virtual NGFW, covering CVE-2026-0266, CVE-2026-0272 and CVE-2026-0273. The flaws include stored cross-site scripting, privilege escalation and OS command injection, with the command-injection bug rated CVSS 7.2. Contractors, defense-industrial-base operators and municipal teams using the appliance should restrict management access and contact support for patch information.

CISA’s advisory is a direct republication of Siemens ProductCERT SSA-104023, and the practical instruction is narrow: organizations running Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW need to treat the PAN-OS issues as appliance issues. The affected product line is listed as all versions. Siemens points customers to Palo Alto Networks’ upstream notices and says to contact customer support for patch and update information.

The highest-rated issue, CVE-2026-0273, lets an authenticated administrator with PAN-OS CLI or web UI access bypass system restrictions and run arbitrary commands as root. CVE-2026-0272 lets an authenticated administrator with CLI access perform actions with root privileges. CVE-2026-0266 is a stored cross-site scripting flaw requiring a malicious authenticated administrator and user interaction. For OT operators, the Monday work is not exotic: limit CLI and management web access to trusted internal IPs, keep control-system devices off the public internet, and verify the Siemens and Palo Alto remediation path for deployed APE1808 units.


Published ·Deep Fathom